Re: [exim] DANE(TA) doesn't work with self signed certificate

2018-09-07 Thread Viktor Dukhovni via Exim-users
> On Sep 7, 2018, at 1:32 PM, Andreas Metzler via Exim-users > wrote: > > Are you positive that this is a problem in GnuTLS and not in a problem > in exim's usage of gnutls-dane? > > Asking, since > danetool --check=lists.gentoo.org --proto tcp --starttls-proto=smtp > succeeds. (I have veri

Re: [exim] DANE(TA) doesn't work with self signed certificate

2018-09-07 Thread Viktor Dukhovni via Exim-users
> On Sep 7, 2018, at 1:19 PM, Jan Ingvoldstad via Exim-users > wrote: > > Additionally, Debian is, in the longer term, in a position to use a > different TLS library than GnuTLS. Debian has historically been ultra-conservative on the potential License compatibility issues between GPL (Exim)

Re: [exim] DANE(TA) doesn't work with self signed certificate

2018-09-07 Thread Andreas Metzler via Exim-users
On 2018-09-07 Viktor Dukhovni via Exim-users wrote: [...] > Until there's either a fix in GnuTLS (Nikos Mavrogiannopoulos can get in touch > with me if there are questions), or a work-around in Exim that disables DANE > for domains with DANE-TA(2) records when linked with GnuTLS (supporting only >

Re: [exim] DANE(TA) doesn't work with self signed certificate

2018-09-07 Thread Jan Ingvoldstad via Exim-users
On Fri, Sep 7, 2018 at 5:50 PM Viktor Dukhovni via Exim-users < exim-users@exim.org> wrote: > > > Though Debian may not be in a possible to fix DANE-TA(2) support in > Exim+GnuTLS, > they may of course be able to bring it to the attention of the apporpriate > GnuTLS developers. This is ultimately

Re: [exim] DANE(TA) doesn't work with self signed certificate

2018-09-07 Thread Viktor Dukhovni via Exim-users
> On Sep 7, 2018, at 3:33 AM, Jan Ingvoldstad via Exim-users > wrote: > > Please, if you have not already done so, file a bug report with Debian, > this is a pretty major bug. Until there's either a fix in GnuTLS (Nikos Mavrogiannopoulos can get in touch with me if there are questions), or a

Re: [exim] Ratelimit database

2018-09-07 Thread Jan Ingvoldstad via Exim-users
On Fri, Sep 7, 2018 at 8:45 AM Andrew C Aitchison via Exim-users < exim-users@exim.org> wrote: > > If "d" is typed at the next prompt, the entire record is deleted. > For all except the retry database, that is the only operation that can be > carried out. This is either out of date, or it's been

Re: [exim] DANE(TA) doesn't work with self signed certificate

2018-09-07 Thread Jan Ingvoldstad via Exim-users
On Wed, Sep 5, 2018 at 5:04 PM Klaus Ethgen via Exim-users < exim-users@exim.org> wrote: > Sure, it is the common debian version and Debian is always linking > against gnutls. > Please, if you have not already done so, file a bug report with Debian, this is a pretty major bug. -- Jan -- ## List

Re: [exim] Ratelimit database

2018-09-07 Thread Heiko Schlittermann via Exim-users
Juan Bernhard via Exim-users (Mi 05 Sep 2018 13:52:07 CEST): > Hello list, I've recently implemented a ratelimit acl on my servers. I would > like to know how to delete an entry for a specific user in the > /var/spool/exim/db/ratelimit database.  If someone took the time to do a > script, and wan